Fortify Development
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.
$ npx skills add spinabot/brigade --skill oauth-setup -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install spinabot/brigade oauth-setup --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/spinabot/brigade.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/oauth-setup .claude/skills/oauth-setup && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "oauth-setup" agent skill from https://github.com/spinabot/brigade/tree/main/skills/oauth-setup into .claude/skills/oauth-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oauth-setup", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/spinabot/brigade/tree/main/skills/oauth-setupType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add spinabot/brigade --skill oauth-setup -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install spinabot/brigade oauth-setup --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/spinabot/brigade.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/oauth-setup .agents/skills/oauth-setup && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "oauth-setup" agent skill from https://github.com/spinabot/brigade/tree/main/skills/oauth-setup into .agents/skills/oauth-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oauth-setup", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add spinabot/brigade --skill oauth-setup -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install spinabot/brigade oauth-setup --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/spinabot/brigade.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/oauth-setup .cursor/skills/oauth-setup && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "oauth-setup" agent skill from https://github.com/spinabot/brigade/tree/main/skills/oauth-setup into .cursor/skills/oauth-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oauth-setup", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/spinabot/brigade.git --path skills/oauth-setup--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add spinabot/brigade --skill oauth-setup -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install spinabot/brigade oauth-setup --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/spinabot/brigade.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/oauth-setup .gemini/skills/oauth-setup && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "oauth-setup" agent skill from https://github.com/spinabot/brigade/tree/main/skills/oauth-setup into .gemini/skills/oauth-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oauth-setup", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install spinabot/brigade oauth-setupInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add spinabot/brigade --skill oauth-setup -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/spinabot/brigade.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/oauth-setup .github/skills/oauth-setup && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "oauth-setup" agent skill from https://github.com/spinabot/brigade/tree/main/skills/oauth-setup into .github/skills/oauth-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oauth-setup", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add spinabot/brigade --skill oauth-setup -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install spinabot/brigade oauth-setup --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/spinabot/brigade.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/oauth-setup .opencode/skills/oauth-setup && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "oauth-setup" agent skill from https://github.com/spinabot/brigade/tree/main/skills/oauth-setup into .opencode/skills/oauth-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oauth-setup", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
oauth-setupConnects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.
The skill tells the agent to use the oauth_authorize tool rather than building a listener by hand. The tool opens a one-time loopback listener on a free port, captures the authorization code and seals the tokens in the credential store. It also names two pitfalls: use a Desktop-app OAuth client, which accepts any loopback redirect without registration, instead of a Web client that triggers redirect_uri_mismatch, and use the real scope URLs, such as the Gmail send scope under googleapis.com.
The flow asks the operator to create a Desktop-app client with the Gmail API enabled and the consent screen in testing, then paste the client ID and secret. The agent starts the flow, with offline access and a consent prompt so a refresh token is issued, sends the returned authorization link to click, and waits for the redirect, repeating the wait if the status is still pending.
Afterwards the tokens cannot be read from files or the database, by design. The agent lists connected accounts with a status action that shows provider, email, scopes and expiry without secrets, and asks for a token action to get a live access token, refreshed automatically, before calling the API, for example to send mail.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4c2a18f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
googleapis.comgmail.comgmail.googleapis.comaccounts.google.comoauth2.googleapis.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
OAuth Account Setup loads about 878 tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 347 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from spinabot/brigade at commit 4c2a18f, republished under its MIT licence (© spinabot). 347 words, ~878 tokens.
.claude/skills/oauth-setup/SKILL.md (or your agent's skills folder).Use the oauth_authorize tool — NEVER hand-roll an http listener in bash. It opens a one-shot loopback listener on a free port (no EADDRINUSE, no port juggling), captures the code, and seals the tokens into the credential store.
http://127.0.0.1:<port> loopback redirect with no redirect-URI registration. A Web client requires the exact redirect URI pre-registered, which is what causes redirect_uri_mismatch.https://www.googleapis.com/auth/gmail.send (NOT https://gmail.com/..., which doesn't exist). Add openid https://www.googleapis.com/auth/userinfo.email if you want the account address auto-filled.oauth_authorize({
action: "start",
provider: "google-gmail",
authorizationEndpoint: "https://accounts.google.com/o/oauth2/v2/auth",
tokenEndpoint: "https://oauth2.googleapis.com/token",
userInfoEndpoint: "https://www.googleapis.com/oauth2/v3/userinfo",
clientId: "<id>", clientSecret: "<secret>",
scopes: ["https://www.googleapis.com/auth/gmail.send", "openid", "https://www.googleapis.com/auth/userinfo.email"],
extraAuthParams: { access_type: "offline", prompt: "consent" }
})access_type=offline + prompt=consent are required for a refresh token (otherwise re-auth is needed when the access token expires).authUrl to click.oauth_authorize({ action: "await", flowId: "<flowId from start>" })pending, the operator hasn't clicked yet — tell them, then call await again.The tokens are sealed in the credential store — you can't read them from a file or the DB, and you shouldn't try. To use a connected account:
oauth_authorize({ action: "status" }) → lists each account (provider, email, scopes, expiry). No secrets.oauth_authorize({ action: "token", provider: "google-gmail" }) → returns accessToken. It auto-refreshes from the sealed refresh token when the old one expired, so you always get a live token. (Pass provider only if more than one account is connected.)POST https://gmail.googleapis.com/gmail/v1/users/me/messages/send, header Authorization: Bearer <accessToken>, body { "raw": "<base64url RFC-822 message>" }.Never cat the credential store, grep for the token, or hand-roll a refresh — action:"token" is the only retrieval path, and it keeps the refresh token + client secret sealed.
© spinabot, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/oauth-setup of spinabot/brigade.
Open the folder on GitHubat commit 4c2a18f
OAuth Account Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| OAuth Account Setup this skillspinabot/brigade | 11k | — | ~878 | Automated safety check: Pass | MIT | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Security Reviewdoorkeeper-gem/doorkeeper | 5.5k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Cognitoitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Auth Implementation Patternsynulihao/AgentSkillOS | 617 | 9 repos | ~4.4k | Automated safety check: Pass | None |
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
doorkeeper-gem/doorkeeper
Verify that code changes do not introduce OAuth security vulnerabilities.
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
ynulihao/AgentSkillOS
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.
hexlet-volunteers/hexlet-sicp
Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.
spinabot/brigade
Shows HTML content such as games, dashboards, visualizations and demos on a connected Brigade node's canvas, using a local canvas host server and a node bridge.
spinabot/brigade
Creates and edits Word documents along four paths of rising capability, from a quick tool to the docx library, an OOXML round-trip and pandoc, then verifies the file.
spinabot/brigade
Writes HTML compositions with a GSAP timeline that the render_video tool turns into deterministic MP4 videos from data, text or layouts.
spinabot/brigade
Diagnoses why a Brigade companion app can't pair or connect, by first identifying the real node-to-gateway route and then fixing auth.
spinabot/brigade
Creates and edits PDFs in Brigade through four paths: a quick content tool, an edit tool for forms and merging, a pdf-lib script for full control, and HTML-to-PDF for styled layouts.
spinabot/brigade
Explains how a skill folder should be laid out and bundled as a tar archive for sharing, with a checklist covering name, description and eligibility keys.
Works with
Categories
Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage. The skill tells the agent to use the oauth_authorize tool rather than building a listener by hand. The tool opens a one-time loopback listener on a free port, captures the authorization code and seals the tokens in the credential store.
OAuth Account Setup fits situations like: connecting a Gmail or Google API account to the agent; fixing a redirect_uri_mismatch error during OAuth; checking which OAuth accounts are connected and when they expire.
Run `npx skills add spinabot/brigade --skill oauth-setup -a claude-code`. Or copy the skill folder (skills/oauth-setup in spinabot/brigade) into .claude/skills/oauth-setup in your project. Claude Code loads it when a task matches its description.
Run `npx skills add spinabot/brigade --skill oauth-setup -a codex`. Or copy the skill folder (skills/oauth-setup in spinabot/brigade) into .agents/skills/oauth-setup in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spinabot/brigade --skill oauth-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oauth-setup, .gemini/skills/oauth-setup, .github/skills/oauth-setup and .opencode/skills/oauth-setup in your project.
SKILL.md names no scripts, command-line tools or credentials: OAuth Account Setup is instructions for the agent only. Our summary lists: A runtime that provides the oauth_authorize tool and a credential store; A Google Cloud Desktop-app OAuth client with the Gmail API enabled.
SKILL.md names 5 domains. In commands or code: googleapis.com, gmail.com, gmail.googleapis.com, accounts.google.com and oauth2.googleapis.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
OAuth Account Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 878 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with OAuth Account Setup: Fortify Development (coollabsio/coolify, 63k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Security Review (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
spinabot (a GitHub organization) maintains it in spinabot/brigade, which has 11,276 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 3, 2026.
Source: spinabot/brigade on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.